Back to skill

Security audit

OpenClaw Safe Update

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent OpenClaw updater, but its Linux workflow can run newly downloaded npm code and a global upgrade with broad system privileges.

Install only if you are comfortable with an updater that downloads and executes OpenClaw from npm. Prefer a pinned target version, use a user-local Node toolchain, avoid running the full script with sudo, and review the script and npm source before using --apply on a production machine.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Error
Location
scripts/openclaw-safe-update.sh:122
Finding

Unverified npm Package Code Can Execute with Elevated Privileges

Content
View full analysis
/dev/null CANDIDATE_ENTRY="$CANDIDATE_DIR/node_modules/openclaw/dist/index.js" [[ -f "$CANDIDATE_ENTRY" ]] || fail "Candidate entry not found: $CANDIDATE_ENTRY" echo "[4/7] Starting sidecar (profile=$SIDECAR_PROFILE, port=$SIDECAR_PORT)..." rm -f "$SIDECAR_LOG" "$NODE_BIN" "$CANDIDATE_ENTRY" --profile "$SIDECAR_PROFILE" gateway --port "$SIDECAR_PORT" --bind "$SIDECAR_BIND" >"$SIDECAR_LOG" 2>&1 & ``` ```bash echo "[7/7] Applying global upgrade + restarting gateway..." $NPM_BIN install -g "openclaw@$LATEST_VERSION" --no-audit --no-fund --loglevel=error >/dev/null ``` The Linux guide recommends elevating the entire script: ```bash # if policy allows and system npm requires it sudo bash scripts/openclaw-safe-update.sh --apply ``` ### Technical Analysis When no explicit target is supplied, the updater obtains a mutable version value from the configured npm registry and installs that package directly. It does not enforce the official registry, compare the downloaded ...[truncated 2187 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/openclaw-safe-update.sh:18
Finding

Predictable PID and Log Files Permit Unsafe File and Process Operations

Content
View full analysis
/dev/null || true rm -f "$SIDECAR_PID_FILE" fi } trap cleanup EXIT ``` ```bash echo "[4/7] Starting sidecar (profile=$SIDECAR_PROFILE, port=$SIDECAR_PORT)..." rm -f "$SIDECAR_LOG" "$NODE_BIN" "$CANDIDATE_ENTRY" --profile "$SIDECAR_PROFILE" gateway --port "$SIDECAR_PORT" --bind "$SIDECAR_BIND" >"$SIDECAR_LOG" 2>&1 & SIDECAR_PID=$! echo "$SIDECAR_PID" > "$SIDECAR_PID_FILE" ``` ### Technical Analysis The script uses fixed filenames in a configurable directory without validating directory ownership, permissions, file type, or symlink status. The PID is persisted to a predictable path and later trusted as the target of `kill` without checking that it is numeric or that the process belongs to the sidecar started by the current invocation. The exit trap is installed before version resolution, package installation, and sidecar startup complete. If a failure occurs after trap installation but before the PID file is overwritten, cleanup can consume a pre-existing PID file and signal an unrelated process. The PID-file redirection also follows a pre-existing symlink. The log file is removed before redirection, which reduces a basic pre-planted symlink attack, but a time-of-check/time-of-use window remains between removal and creation. Risks increase when `LOG_DIR` points to a shared or attacker-writable loca ...[truncated 1534 chars]
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill instructs execution of shell commands and a bundled bash script, but it does not declare any tool scope such as permissions or allowed-tools. That creates an authorization gap where an agent may invoke shell capabilities without explicit restriction, reducing reviewability and increasing the chance of unintended command execution in a sensitive update workflow.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The guide explicitly instructs users to perform an upgrade that relies on a global npm install and even shows a sudo-based invocation, but it does not clearly warn about the security and system-wide consequences of elevating privileges and modifying globally installed tooling. In a software update skill, this is risky because users may copy-paste privileged commands that change shared runtime state, potentially affecting other packages or trusting whatever the update script fetches.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/linux.md (reported line 39)May include surrounding context.

md
`--apply` uses global npm install (`npm install -g`). Depending on your Node setup:

- With `nvm`/user-local Node: usually no sudo needed
- With system Node: you may need sudo or a writable global prefix

Examples:

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/linux.md (reported line 40)May include surrounding context.

md
`--apply` uses global npm install (`npm install -g`). Depending on your Node setup:

- With `nvm`/user-local Node: usually no sudo needed
- With system Node: you may need sudo or a writable global prefix

Examples:

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
50% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/linux.md (reported line 40)May include surrounding context.

md
`--apply` uses global npm install (`npm install -g`). Depending on your Node setup:

- With `nvm`/user-local Node: usually no sudo needed
- With system Node: you may need sudo or a writable global prefix

Examples:

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
88% confidence
Finding

This line gives a concrete copy-pastable command that runs the update script under sudo, which elevates the trust boundary from a user-scoped check to full system modification. In the context of an updater skill, encouraging privileged execution is dangerous because any flaw in the script, package source, or dependency chain could lead to system-wide compromise.

Content

Scanner excerpt · references/linux.md (reported line 49)May include surrounding context.

npm config get prefix

if policy allows and system npm requires it

sudo bash scripts/openclaw-safe-update.sh --apply

text

## Troubleshooting

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

In apply mode, the script performs a global npm install and restarts the gateway, which changes the user's system state beyond the isolated verification step. Although the help text mentions 'apply global upgrade,' there is no explicit warning or confirmation at the point of execution about modifying the global installation and restarting the service.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.